icon
icon
icon
icon
$300 Off
$300 Off

News /

Articles /

Cryptocurrency Users Targeted by Malware Disguised as TradingView Crack

Coin WorldWednesday, Mar 19, 2025 10:22 pm ET
1min read

Cryptocurrency users have been targeted by a sophisticated malware campaign disguised as a cracked version of the popular trading platform TradingView. This malicious software, distributed through reddit posts, aims to steal personal data and cryptocurrency wallet information from both Mac and Windows users. The scammers lure victims by offering free access to TradingView, claiming that the software has been cracked to unlock premium features. These posts are found on subreddits frequented by cryptocurrency traders, where the scammers post links to installers that are laced with Lumma Stealer and Atomic Stealer (AMOS) malware.

The malware is distributed through links hosted on an unrelated website, which belongs to a Dubai cleaning company. This website is running an outdated PHP version, making it vulnerable to exploitation. The files are double zipped and password protected, a tactic used to evade security scanners. On Mac, the installer is a new variant of AMOS, which checks for the presence of virtual machines and exits if detected. The malware exfiltrates user data via a POST request to a server hosted in the Seychelles. On Windows, the payload is loaded via an obfuscated bat file that runs a malicious Autoit script, with the command and control server registered in Russia.

Victims of this malware have reported that their crypto wallets were emptied, and their identities were impersonated to send phishing links to their contacts. This campaign highlights the ongoing threat of cracked software containing malware, despite decades of warnings. The scammers are actively engaged in the Reddit threads, posing as helpful users to assist victims and encourage downloads. To stay safe, users should be wary of instructions to disable security software, password-protected files, and files hosted on dubious online platforms. Malwarebytes offers protection against both Mac and Windows payloads, helping to keep threats off devices.

This incident underscores the importance of vigilance among cryptocurrency users. The lure of free or cracked software can be tempting, but the risks are significant. Users must be cautious about downloading software from unknown sources and should always verify the legitimacy of any software they intend to install. The use of reputable security software and staying informed about the latest threats can help protect against such malicious campaigns. Cryptocurrency users should also be aware of the tactics used by scammers, such as posing as helpful users in online forums, and should avoid engaging with suspicious links or downloads.

Comments

Add a public comment...
Post
User avatar and name identifying the post author
OkFirefighter1110
03/20
Cracked software? More like 'cracked open' wallets for crypto thieves
0
Reply
User avatar and name identifying the post author
Gix-99
03/20
@OkFirefighter1110 Guess they're going for a 'ining' operation instead of actual trading.
0
Reply
User avatar and name identifying the post author
oakleystreetchi
03/20
Lol, who needs TradingView when you have proper research skills? Let's keep our data safe.
0
Reply
User avatar and name identifying the post author
Ironman650
03/20
Remember, if it seems too good to be true, it probably is. Crypto world needs more awareness.
0
Reply
User avatar and name identifying the post author
Megadragon1604
03/20
@Ironman650 Fair enough
0
Reply
User avatar and name identifying the post author
ZestycloseAd7528
03/20
Malwarebytes to the rescue! Protect those devices, peeps. Better safe than sorry.
0
Reply
User avatar and name identifying the post author
khasan14
03/20
Free TradingView? Sounds too good to be true.
0
Reply
User avatar and name identifying the post author
Mylessandstone69
03/20
Who'd fall for this? Only clicked a link once, lucky me.
0
Reply
User avatar and name identifying the post author
Sgsfsf
03/20
Scammers always find new ways to mess with us. Stay vigilant, folks. Never click shady links.
0
Reply
User avatar and name identifying the post author
Buffet_fromTemu
03/20
I'm all in on $TSLA and $AAPL. No time for sketchy crypto apps. Keep it legit, y'all.
0
Reply
User avatar and name identifying the post author
cfeltus23
03/20
Keep your software updated, don't be a noob.
0
Reply
User avatar and name identifying the post author
OG_Time_To_Kill
03/20
Malware scum targeting crypto folks, be careful!
0
Reply
User avatar and name identifying the post author
BeefMasters1
03/20
@OG_Time_To_Kill Fair enough
0
Reply
Disclaimer: the above is a summary showing certain market information. AInvest is not responsible for any data errors, omissions or other information that may be displayed incorrectly as the data is derived from a third party source. Communications displaying market prices, data and other information available in this post are meant for informational purposes only and are not intended as an offer or solicitation for the purchase or sale of any security. Please do your own research when investing. All investments involve risk and the past performance of a security, or financial product does not guarantee future results or returns. Keep in mind that while diversification may help spread risk, it does not assure a profit, or protect against loss in a down market.
You Can Understand News Better with AI.
Whats the News impact on stock market?
Its impact is
fork
logo
AInvest
Aime Coplilot
Invest Smarter With AI Power.
Open App